Index one OneDrive, or one folder in it, through a Microsoft 365 app registration. Files are read the same way as File Uploads.

Before you start

  • A Pro or Enterprise plan.
  • A Microsoft 365 tenant, and an admin who can grant consent to an app registration.
  • The Edit Sources permission on the knowledge base. Owners and admins always have it. See Roles & Permissions.

Set up

1

Register an app

In the Azure portal, open Microsoft Entra ID → App registrations → New registration. Copy the Application (client) ID and the Directory (tenant) ID.
2

Grant Files.Read.All

Under API permissions, add the application permission Files.Read.All. Ask an admin to grant consent for the tenant.
3

Create a client secret

Under Certificates & secrets, create a client secret. Copy its value now — Azure shows it only once.
4

Add the source

In Kelu, open the knowledge base, go to Sources → Add source, pick OneDrive and click Continue. Enter a Display name, then fill in the fields below. Click Test connection, then Add source.

Settings

FieldRequiredDescription
Tenant IDYesThe Directory (tenant) ID.
Client IDYesThe Application (client) ID.
Client SecretYesThe secret value from Certificates & secrets.
User emailEmail or Drive IDWhose OneDrive to index, for example alice@acme.com.
Drive IDEmail or Drive IDUse instead of an email for a shared or secondary drive.
FolderNoA path such as Documents/Handbook. Empty indexes the whole drive.

What gets indexed

  • Every file in the drive or folder, subfolders included, of these types: .pdf .docx .xlsx .xlsm .xltx .xltm .csv .tsv .html .htm .md .mdx .txt.
  • Each file becomes one document, linked to the file in OneDrive and titled with its file name.
  • Other types (such as .pptx and old .xls), files over 32 MB and files with no readable text are skipped. Sync history lists each skipped file and why.
New documents are public unless the knowledge base is internal. To keep them for workspace members only, set Visibility to Restricted when you add the source. Later, open Configuration → Edit and set New documents to Restricted. That applies to files indexed after the change.

Sync

OneDrive syncs every 10 minutes. Files that have not changed are not downloaded again. Sync Now on the source page runs a sync at once.

Troubleshooting

  • “The app registration was refused” — admin consent for Files.Read.All is missing, or the secret is wrong or expired. Fix it in Entra ID, then update Client secret under the source’s Configuration tab.
  • “No drive found” — the email has no OneDrive yet. Use the person’s sign-in name, or set Drive ID.
  • “Could not read folder” or “folder is empty” — check the Folder path. It must match exactly, for example Documents/Handbook.
  • Some files are missing — open Sync history and click “Not indexed: N entries” to see each one and why.